Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68f5-49rw-qgq9

Опубликовано: 19 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

EPSS

Процентиль: 36%
0.00152
Низкий

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

EPSS

Процентиль: 36%
0.00152
Низкий

Дефекты

CWE-640